Saturday, March 12, 2016

CFPB Supervisory Highlights Hone in on Credit Reporting and Student Loan Servicing


The CFPB published its Winter Supervisory Highlights last week, highlighting examinations across various financial products that were conducted between September 2015 and December 2015.  The Report highlights key findings made by the CFPB and provides insight into the current focus of examiners.  The Report makes clear that the CFPB remains concerned with credit reporting issues involving depository accounts and that supervision of the student loan servicing market remains a priority.  The Report also makes clear that where there is no specific regulatory authority, the CFPB will fall back on its UDAAP (unfair and deceptive practices) umbrella to regulate as it deems necessary.  Good news for debt collectors and mortgage servicers, the primary focuses of the Report are credit reporting and student loan servicing. The CFPB noted the following issues worthy of mention:

CREDIT REPORTING DEPOSITORY ACCOUNTS
  • Banks and Credit Unions continue to struggle with accurately furnishing information to nationwide specialty consumer reporting agencies and specifically, with regard to depository accounts.  As we indicated in a prior blog post, the CFPB continues to be concerned with the furnishing and reporting of information related to deposit accounts.  The Report again emphasizes the need for banks and credit unions to implement reasonable written policies and procedures regarding the accuracy and integrity of the information they are furnishing as to deposit accounts and promptly update information they determine is incomplete or inaccurate.
  • The Report also indicates that examiners are concerned that specialty consumer reporting agencies are not adequately overseeing furnishers.
DEBT COLLECTION
  • Debt collectors may want to review their data migration systems and employee training regarding cease and desist requests.  The Report notes that examinations found at least one debt collector who contacted consumers after receiving written cease and desist requests.  The report attributed the failure to data migration errors and from mistakes during manual data entry.
  • The Report also noted that specific to student loan collection, their examiners found in at least one examination, debt collectors falsely threatening garnishment. 
STUDENT LOAN SERVICING
  • As to student loan servicers, the Report makes clear that student loan servicing is going to be an emphasis for the CFPB in coming months.  According to the CFPB news release, “[t]he CFPB has made it a priority to police this market so that borrowers ae not treated unfairly or illegally dead-ended into default.” Significant to the Report:

o   The CFPB examiners found unfair practices in violation of Dodd Frank where one or more servicers auto defaulted both the borrower and the co-borrower if the other filed bankruptcy.  The CFPB concluded that the “auto-defaults were unfair where the whole loan due clause was ambiguous on this point because reasonable consumers would not likely interpret the promissory notes to allow their own default based on a co-debtor’s bankruptcy.”  Supervisory Highlights, p. 16 (10th Ed. Winter 2016).

o   The CFPB identified issues with loan conversions, suggesting that interest rates were migrated inaccurately by some loan servicers.

o   The CFPB identified weaknesses with loan servicers’ policies and procedures for credit reporting.  Particularly, the CFPB examinations noted insufficient policies and procedures regarding record retention, internal controls, audits and testing, and technology to furnish information accurately to consumer reporting agencies.


Banks and credit unions should pay close attention to the volume of comments being provided by the CFPB concerning credit reporting and depository accounts.  This is the second consecutive Supervisory Highlight edition to note the issue and the CFPB has additionally issued a Compliance Bulletin this year on the subject.

Thursday, March 10, 2016

Guest Post: The Little Engine that CAN Make a Difference


By: Mark Dobosz
March 8, 2016"It would seem that legislative canon that purports to better regulate those institutions deemed 'too big to fail' is unwittingly creating a class of banks that may be 'too small to succeed.'" 

                M&T CEO Bob Wilmers in his latest annual letter to shareholders.


I personally would credit the genesis of the phrase “too small to succeed” to Immediate Past-President of the National Creditors Bar Association, Joann Needleman, as she frequently spoke and continues to speak on the increasing costs of regulation and the impact on the creditors rights attorney firms and the industry. It is a welcoming sight to see that our fellow colleagues on the small banking side are also joining in with a loud call to rein in federal regulations to stem the tide of putting small and medium sized businesses and firms “out of business”.

Bob Wilmers went on to say in his letter, "We have witnessed, through the rise of nonbank players, a subtle but steady shift in which regional banks are playing an ever-diminished role in the financial leadership of the communities and small towns of America that they have traditionally served so well," Wilmers went on to say 

"Such is the collateral damage of far-reaching regulation inspired by the misdeeds of a few."

                                                         M&T CEO Bob Wilmers

 A recent blog article I wrote applauded the federal government for going after a “bad actor” in the debt collection industry. This was a prime example of how enforcement of existing laws and regulations can truly clean up the landscape and focus on the “misdeeds of a few”. We truly don’t need more regulation to expel the bad players, we need to, as Harvey Moore, President of the National Creditors Bar Association, reminds us – “Enforce and execute the existing laws and regulations we already have on the books”.
 
“Today we face a turning point,” Wilmers said. “Will we continue to look for villains to punish or will we take steps that will enable banks to serve again as agents of an expanding prosperity?”
 
The cooperation between industry groups and the regulatory bodies, which enforce laws to eliminate those who consciously harm consumers through deceptive practices, is a mutual goal we want to continue to pursue together. If we force too many “good players” out because of increasingly costly regulations – small banks or small creditors rights attorney firms – to become “too small to succeed”, then we risk causing consumers more harm than good.



About the Author:  Mark Dobosz currently serves as the Executive Director for NARCA – The National Creditors Bar Association. Mark is a one of NARCA’s speakers on many of the creditors rights issues impacting NARCA members. The National Creditors Bar Association (NARCA) is a trade association dedicated to creditors rights attorneys. NARCA's values are: Professional, Ethical, Responsible


Sunday, March 6, 2016

No Consumer Harm? No Direct Enforcement Authority? No Problem – CFPB Enters into Consent Order with Dwolla


This week, the CFPB made its first foray into the data privacy arena by entering into a Consent Order with online payment processor, Dwolla. Inc. via an administrative proceeding.  The Consent Order sends a clear message across the consumer financial services arena that the CFPB will use its UDAAP umbrella to extend its reach and that no consumer harm is required for the CFPB to flex its muscle.

According to the CFPB, it took action because Dwolla “deceived consumers about its data security practices and the safety of its online payment system.”  Without admitting any wrongdoing, the Consent Order includes findings that Dwolla collected and stored consumers’ private information and provided a platform for financial transactions.  According to the findings, Dwolla represented that it maintained “reasonable and appropriate measures to protect data obtained from consumers from unauthorized access.”  However, the CFPB concluded that Dwolla in fact did not take reasonable and appropriate measured to protect consumer data. Specifically, the Order finds that, among other things:

·        For a significant period of time, Dwolla did not adopt or implement reasonable and appropriate data-security policies and procedures to govern the collection, maintenance or storage of consumers’ personal information;

·        For a significant period of time, Dwolla failed to conduct adequate regular risk assessments to identify reasonably foreseeable internal and external risks to information and to assess the safeguards in place to control these risks;

·        For a significant period of time, Dwolla did not provide adequate employee training as to the handling and protection of consumers’ personal information;

·        For a significant period of time, Dwolla transmitted consumers’ personal information without encrypting it; and

·        For a significant period of time, Dwolla did not adequately manage its vendors as to data security.

Pursuant to the Consent Order, Dwolla is required, to the extent it has not done so already:

·        Accurately represent in its marketing, advertising, promotion or administration of its electronic payment networks the data security practices implemented by Dwolla;

·        Implement a comprehensive Written Information Security Plan which mirrors the requirements of GLBA’s Safeguard Rules and which:

o   Designates a qualified person to coordinate its data security program;

o   Identifies reasonably foreseeable internal and external risks to the security and confidentiality of consumer nonpublic information and assess the sufficiency of the institution’s  safeguard in place to control those risks, including risks in areas of operation specifically:

§  Employee training and management; and

§  Confidentiality and integrity of Dwolla’s network systems or apps and storage systems;

o   Implement safeguards to manage the identified risks and regularly test and monitor risks;

o   Develop, implement and maintain reasonable procedures for the selection and retention of service vendors capable of maintaining security practices consistent with the Consent Order; and

o   Evaluate and adjust the data security program in light of the results of the risk assessments and monitoring.

·        Retain a third party independent auditor to conduct an annual data-security audit of Dwolla’s data security practices; and

·        Pay a civil monetary penalty of $100,000.00.

Several things make this order significant and banks and nonbanks alike should take note:

·        Prior to this action, there had been no indication by the CFPB, either through its website or other publications, that it was focused on data security leading many to assume they would defer to the FTC and other regulators on issues of data privacy;

·        Gramm Leach Bliley and its Safeguard Rules (which provide for the protection of consumer nonpublic information by financial service providers) are not among the enumerated consumer protection statutes over which the CFPB has jurisdiction;

·        The Consent Order reflects the CFPB’s position that its UDAAP (unfair and deceptive acts) umbrella liability is expansive enough to take on data security issues; and

·        The Consent Order makes no finding of a data breach or some other sort of consumer or injury.  

Banks and nonbanks alike should pay close attention to the Dwolla Order and expect to see the CFPB continue take expansive views of its authority to regulate.

Wednesday, March 2, 2016

FTC Agrees to Settles with Hardware and Software Provider over Data Privacy Breaches


A recent settlement by the FTC with the manufacturer of computer routers serves as a reminder to all that in the growing Internet of Things, it is critical for companies to place adequate security measures in place to protect consumer’s private data. The FTC’s latest proposed consent order targets Taiwan based computer hardware maker ASUSTek Computer, Inc.  (“ASUS”).  ASUS manufactured and sold home routers and related software and services for consumer use.  ASUS’s routers included software features that allowed consumers to wirelessly access and share files through their routers.  The FTC complaint contends that the software was prone to multiple vulnerabilities and that critical security flaws with the routers “put the home networks of hundreds of thousands of consumers at risk.”  FTCPress Release: ASUS Settles FTC Charges that Insecure Home Routers and “Cloud”Services Put Consumers’ Privacy at Risk (Feb. 23, 2016).

With no admission of liability, the parties have agreed to a proposed consent order which requires ASUS to adopt a comprehensive security program subject to independent audits for the next twenty years.  Here are the key takeaways:

  • Take Reasonable Steps to Secure Software Features from Vulnerabilities.  According to the complaint and proposed consent order, ASUS did not take reasonable steps to secure its routers and their software add-ons.  The FTC showed particular concern that the products at issue were routers which the FTC noted “typically function as a hardware firewall for the local network, and act as the first line of defense in protecting consumer devices on the local network”.  The ASUS routers at issue were preset with the same default username and password and their add on software’s web applications included multiple vulnerabilities which would allow unauthorized access with only the router’s IP address, information the FTC contended was easily discoverable.
     
  • Put Processes in Place to Promptly Address Security Vulnerabilities.  According to the complaint and proposed consent order, ASUS did not address security flaws in a timely manner and did not notify consumers of the risks posed.  The FTC alleges that updated firmware was provided initially only to affected routers and the updates were not made available to all registered users until several months later. 
     

The Consent Order should be reviewed by all companies involved in the Internet of Things as a risk management tool.  It requires:

  • ASUS to fully and accurately to make disclosures to consumers regarding the extent to which the company or its products or services maintain:
    • The security of any covered device;
    • The security, privacy, confidentiality or integrity of any covered information;
    • The extent to which a consumer can use a covered device to secure a network; and
    • The extent to which a device is using up to date software.
       
  • ASUS to develop and maintain a comprehensive written security program (“WISP”) reasonably designed to address security risks related to the development and management of their devices and to protect the privacy, security, confidentiality and integrity of consumer information.  The WISP should, among other things:
    • Identify internal and external risks to privacy, security, confidentiality and integrity of consumer personal information; and the identification of risks should take into consideration all relevant operations, including product design, development and research and secure software design development
    • Identify internal and external risks to security of their devices what could result in unauthorized access and the identification of risks should take into consideration all relevant operations, including product design, development and research and secure software design development;
    • Assess the company’s processes in reviewing, assessing and responding to both third party security vulnerability reports and to attacks, intrusions or system failures;
    • Design and implement safeguards from the outset to identify potential security failures and verify that access to devices and consumer information is restricted consistent with a user’s security settings;
    • Regularly test and monitor the effectiveness of the safeguards’ key controls, systems and procedures;
    • Continue to evaluate and adjust the WISP as needed in light of the results of testing and monitoring.

Tuesday, March 1, 2016

CFPB Monthly Report Turns its Attention to Prepaid Products




The CFPB issued its Monthly Report this week. The report is a high level snapshot of trends in consumer complaints and provides a summary of the volume of complaints by product category, by company and by state. Additionally, each month it highlights a product type and a geographic area. This month’s report highlights credit card products and provides some forecasting of areas regulators are likely to focus on in upcoming examinations. 
 
Each month, the Report breaks down complaint volume by product looking at a three month average and comparing the same to the prior year. As has been the case in prior months, the Report continues to indicate that the three products yielding the highest volume of complaints are debt collection, mortgage and credit reporting with debt collection complaints representing 31 % of the complaints submitted in January. In the year to year comparison, Arizona, Delaware and North Carolina experienced the greatest complaint volume increase.
 
This month’s report focuses on prepaid cards which is ironic considering that the Report indicates that prepaid card complaint showed the least month-over-month increase. However, it does confirm our observation that the product highlight is rotating through the various products tracked through the complaint portal. According to the CFPB Reports, prepaid cards make up only a minimal portion of all complaints submitted. Since July of 2011, only 4300 prepaid card complaints have been filed (or 0.5% of the total complaints).  
 
The most common issues identified by consumers are managing, opening or closing an account and unauthorized transactions or other transaction issues. Specifically, 
 
  • According to the report, consumers complained that they were unable to access funds loaded on their prepaid cards for an extended period of time;
  • Consumers complained about expired prepaid cards where companies refused to reissued cards with remaining balances where the expiration or valid through date was embossed on the cards;
  • Consumers also complained about transaction and other fees; and
  • Consumers also raised concerns that where they disputed charges, companies freeze the entire balance to prevent further loss while the claim is being reviewed.
 
Another issue worth noting is the CFPB’s observation that scammers are instructed consumers to purchase prepaid cards in order to transfer funds to the fraud perpetrators.
 
 
 

Second Circuit: State and Local Law Violations Do Not Create Per Se FDCPA Violations


In a rather odd opinion, the Second Circuit Court of Appeals joined the majority of federal circuits who have held “that violations of state and local debt collection statutes are not per se actionable under the FDCPA.”  Gallego v. Northland Group Inc., 15-1666-cv, 2016 U.S. App. LEXIS 3025 (2nd Cir. Feb. 22, 2016).  In Gallego, the consumer filed a putative class action against a collection agency alleging that the collection letter violated the FDCPA.  Specifically, the plaintiff alleged that because the collection letter provided a telephone number to call the defendant but did not provide the name of any person who the plaintiff could speak to, the letter violated sections 1692e(10) and 1692f. Neither cited provision requires debt collectors to include names of individuals the consumer can speak to if he calls in, however, the New York City Administrative Code does.  Plaintiff contended that because the letter violated the NYC Administrative Code, the debt collector violated the FDCPA. The case came before the district court after the parties reached a tentative class settlement seeking conditional approval of the class wide settlement and certification of the conditional settlement class.  The District Court dismissed the plaintiff’s complaint sua sponte for lack of subject matter jurisdiction after denying plaintiff’s class certification. 

On appeal, the Second Circuit reversed and remanded the case to the trial court for further proceedings disagreeing with the district court’s basis for dismissal.  In doing so, the court differentiated between a lack of subject matter jurisdiction and a mere failure to state a proper claim, nothing that courts have been cautioned against collapsing the distinction between failing to raise a substantial federal question for jurisdictional purposes and failing to state a claim on the merits.   “The level of frivolity required for a federal claim to fail to invoke federal subject matter jurisdiction” is wholly insubstantial or obviously frivolous.  Shapiro v. McManus, 136 S. Ct. 450, 455 (2015).  “Unless a claim fails to clear even that low bar…”the failure to state a proper cause of action calls for a judgment on the merits and not for a dismissal for want of jurisdiction.” That is what the district court should have done.”  Gallego at *8 (internal citations omitted). 

In the eyes of the Second Circuit, the complaint in this instance was failed to state a proper claim. The court held that neither of the cited sections of the FDCPA would support a claim.  The FDCPA specifically preempts state laws which do not provide as much protection as the FDCPA, but any state laws which provide more protection than the FDCPA are allowed. This provision (§1692n) would not be needed if the FDCPA incorporated state laws.  The court found that the failure to provide the name of an individual a consumer could speak to when calling the debt collector was not a false representation or deceptive under § 1692e(10) or unfair and unconscionable under § 1692f.  As such, on remand the District Court will most assuredly see the defendant file a 12(b)(6) motion to have the complaint dismissed for failure to state a claim.  This is another positive case for debt collectors as another Circuit finds that the state and local law violations are not per se violations of the FDCPA.